#!/usr/bin/bash

( grep -Psq "\-w\s+\/var\/log\/lastlog\s+\-p\s+wa\s+(\-k\s+.*)" /etc/audit/rules.d/*.rules /etc/audit/*.rules && grep -Psq "\-w\s+\/var\/run\/faillock\s+\-p\s+wa\s+(\-k\s+.*)" /etc/audit/rules.d/*.rules /etc/audit/*.rules && auditctl -l | grep -Psq "\-w\s+\/var\/log\/lastlog\s+\-p\s+wa\s+\-k\s+.*" && auditctl -l | grep -Psq "\-w\s+\/var\/log\/lastlog\s+\-p\s+wa\s+\-k\s+.*" && echo 'pass' ) || echo 'fail'